Our client uses Cortex XDR and I would recommend turning on Enhanced Application Logs, but want to make sure that this would not change the formatting for the logs exported through syalog.
Thanks!
1 comment
Comments (1)
Commenting on this post isn't available anymore. Contact the site owner for more info.
It should make additional headers available for forwarding. If you have customized syslog headers you'll need to add them, else they'll be included